Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,263 rules
Windows Process Initiated Connections to Ngrok Domains
Alerts when a Windows process initiates an outbound connection to ngrok domain hostnames, which may indicate staging or C2 activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh122Free2022-07-16Windows Scheduled Task Creation Triggered Once at 00:00 Using Scripted Commands
Alerts on suspicious schtasks.exe task creation for a one-time 00:00 run with embedded script/command execution strings.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-07-15Sysmon DNS Query for anonfiles.com Domain
Flags Windows Sysmon DNS queries referencing anonfiles.com to support detection of suspicious data staging.
pH-T (Nextron Systems), Huntrule TeamWindowsdns_queryHigh101Free2022-07-15Windows Suspicious Service Creation via sc.exe or PowerShell New-Service with Abnormal Binary Paths
Flags service creation commands (sc.exe/New-Service) when the specified binary path includes suspicious directories or script/loader utilities.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2022-07-14Windows: Detect sc.exe Creating Kernel Driver Services
Flags sc.exe service creation where the command-line specifies a kernel driver type and binPath.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium264Free2022-07-14MSSQL sp_procoption Startup Execution Set/Clear via Application Log EventID 33205
Alerts on MSSQL sp_procoption being set or cleared for automatic startup execution via EXEC (EventID 33205).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh91Free2022-07-13Windows/MSSQL: Detect ALTER SERVER AUDIT or DROP SERVER AUDIT executions
Alerts on MSSQL ALTER/DROP SERVER AUDIT statements that disable or delete server audit coverage.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh376Free2022-07-13Windows MSSQL: Add Member to sysadmin Server Role (EventID 33205)
Alerts on MSSQL EventID 33205 when an ALTER SERVER ROLE command adds a member to the sysadmin role.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh133Free2022-07-13Windows Registry: Hidden User via Winlogon SpecialAccounts Userlist Value 0
Alerts on Windows registry updates that set Winlogon SpecialAccounts Userlist to DWORD 0 to hide users.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsregistry_setHigh141Free2022-07-12Windows: Base64-Encoded PE “MZ” Header Present in Command Line
Alerts when Windows command lines include Base64 strings matching a PE “MZ” header.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh278Free2022-07-12Windows: Local user creation via net.exe with expires:never
Flags net.exe user add commands that set expires:never for local account persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2022-07-12Windows: Detect Suspicious mofcomp.exe Execution from Scripts or Temp Paths
Flags mofcomp.exe runs spawned by script interpreters or using temp/AppData paths, with exclusions for WmiPrvSE .mof-related activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-07-12Windows cmd.exe Output Redirection to User Writable Paths
Flags cmd.exe commands that redirect output (>) into temp/AppData and other commonly targeted directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium124Free2022-07-12Windows MSSQL xp_cmdshell Setting Change (EventID 15457)
Flags MSSQL xp_cmdshell setting changes using Windows application EventID 15457 events containing 'xp_cmdshell'.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh2210Free2022-07-12Windows MSSQL xp_cmdshell Command Execution via Application Event 33205
Alerts when SQL Server xp_cmdshell is invoked to execute commands, using Windows application EventID 33205 data.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh156Free2022-07-12